Carderbee — APT Profile
Carderbee is a cyber-espionage cluster first documented by Symantec's Threat Hunter Team in April 2023, when researchers observed a software supply-chain compromise of Cobra DocGuard, a data encryption/decryption product made by the Chinese firm EsafeNet. The tampered update mechanism reached roughly 2,000 machines, mostly in Hong Kong with additional victims elsewhere in Asia, but the group pushed a second-stage backdoor to only about 100 of those systems, indicating deliberate, high-value target selection rather than indiscriminate compromise. The second-stage payload was a version of the PlugX/Korplug backdoor, supporting command execution, file enumeration and exfiltration, process monitoring, firewall manipulation, and keylogging; some of the loader components were signed with a legitimate Microsoft Windows Hardware Compatibility Publisher certificate to aid evasion. Because PlugX/Korplug is shared across numerous China-linked threat groups, Symantec assessed a likely (but unconfirmed) connection to the Chinese threat ecosystem, while explicitly stating it found insufficient evidence to attribute the campaign to any previously known actor. Notably, an earlier and separate 2021-2022 abuse of the same Cobra DocGuard supply chain had been attributed to LuckyMouse/APT27/Budworm, but Symantec found no conclusive link between that prior activity and the April 2023 Carderbee intrusion set, and continues to track Carderbee as a standalone cluster.
Vendor research
Countries linked to this actor
Read the full analysis on IntelFusions